CosmosEscape: Taking Over Every Database in Azure Cosmos DB
Summary
Wiz Research reveals CosmosEscape, a critical vulnerability in Azure Cosmos DB via the Gremlin API that could have granted read and write access to every database. The attack chain leveraged a platform-wide Cosmos Master Key and a Config Store to enumerate accounts and access data; Microsoft remediated the issue and eliminated the master key, with additional guardrails and architectural fixes rolled out across regions. The post emphasizes responsible disclosure, enterprise risk, and the importance of defense-in-depth in cloud databases.